Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2018-06-04 18:15:21

Wyjec
Contributor
Registered: 2018-06-02
Posts: 10

iclass authentication

Hi, my manager gave me a challenge. He wanted me to prove, that I could successfully enter our office by cloning a legit card (iclass elite) that is added to our access control system. He gave me a blank card to clone my corporate badge into. I easily dumped all the data from my badge. But the CSN number can't be override. And I assume that if the CSN number doesn't match, I won't be authenticated and it's game over?

Offline

#2 2018-06-06 06:09:21

marshmellow
Contributor
From: US
Registered: 2013-06-10
Posts: 2,302

Re: iclass authentication

If you are working with a legacy iclass system the standard data is likely encrypted and diversified with the uid, so a different uid means invalid data, unless you can decrypt it and reencrypt it using the key and new uid.

But some elite systems don't use the encrypted pac data, and just have it plain text. So it might not be necessary.

Offline

#3 2018-06-06 11:06:49

Wyjec
Contributor
Registered: 2018-06-02
Posts: 10

Re: iclass authentication

My mistake - we use legacy iclass, and yeah - surprisingly I succeed with authentication using different CSN:)

Offline

Board footer

Powered by FluxBB